Beveiligingsadvies

CVE-2020-11976

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-08-11 18:15:51
Laatst bijgewerkt 2024-08-04 11:48:57
Toegewezen door apache
CVSS-score geen score
Status PUBLISHED

Beschrijving

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5